CVE-2013-1167
Cisco IOS XE 3.2 through 3.4 before 3.4.2S, and 3.5, on 1000 series Aggregation Services Routers (ASR), when bridge domain interface (BDI) is enabled, allows remote attackers to cause a denial of service (card reload) via packets that are not properly…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.96%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cisco IOS XE 3.2 through 3.4 before 3.4.2S, and 3.5, on 1000 series Aggregation Services Routers (ASR), when bridge domain interface (BDI) is enabled, allows remote attackers to cause a denial of service (card reload) via packets that are not properly handled during the processing of encapsulation, aka Bug ID CSCtt11558.
- CVSS 2.0
- 7.1 HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
- EPSS
- 1.96% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- cisco/ios xe · cisco/asr 1001 · cisco/asr 1002 · cisco/asr 1002-x · cisco/asr 1002 fixed router · cisco/asr 1004 · cisco/asr 1006 · cisco/asr 1013 · cisco/asr 1023 router
- Source
- psirt@cisco.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.